generated: '2026-08-12' method: searched probe: true source: https://security.salesforce.com/responsible-disclosure-policy/ ownership_note: >- Salesforce acquired Datorama in August 2018 and operates it as Marketing Cloud Intelligence, so the vulnerability-disclosure programme covering the Datorama platform is Salesforce's — the same compliance site publishes a "Vulnerability/Penetration Report Summary - MC Intelligence (fka Datorama)" document under the Marketing Cloud - Intelligence service, which ties the programme to this product by name. policy: - https://security.salesforce.com/responsible-disclosure-policy/ contact: - https://security.salesforce.com/contact-us/ security_txt: false security_txt_note: >- No /.well-known/security.txt is served on datorama.com, www.datorama.com, api.datorama.com, platform.datorama.com or developers.datorama.com — nor on www.salesforce.com (404). See well-known/datorama-well-known.yml. bug_bounty: public_program: false platform: null note: >- No HackerOne / Bugcrowd / Intigriti programme is linked from the policy page. Submission is via the "Security Vulnerability Finding Submittal Guide" process rather than a bounty platform. safe_harbor: present: true statement_verbatim: >- "Salesforce pledges not to initiate legal action against researchers for penetrating or attempting to penetrate our systems as long as they adhere to this policy." policy_highlights: - verbatim: >- "Independent security researchers play a valuable role in internet security. As a result, we encourage responsible reporting of any vulnerabilities that may be found in our site or applications." - verbatim: >- "As a component of responsible disclosure, Salesforce will notify potentially impacted customers when they must take action to patch or otherwise remediate a vulnerability in advance of publicly disclosing the issue and releasing a Common Vulnerabilities and Exposures (CVE)." - verbatim: >- "Whenever a Trial or Developer Edition is available, please conduct all vulnerability testing against such instances. Always use test or demo accounts when testing our online services." - verbatim: >- "Privately share full details of the suspected vulnerability with the Salesforce Security team by following the Security Vulnerability Finding Submittal Guide process." prohibited_research: - Actions that may negatively affect Salesforce or its users (spam, brute force, denial of service) - Accessing or attempting to access data that does not belong to the researcher recognition: contributors_page: https://security.salesforce.com/security-research-contributors/ note: Salesforce publishes a list of security research contributors. evidence: - {source: 'https://security.salesforce.com/responsible-disclosure-policy/', http_status: 200, kind: disclosure-policy, fetched: '2026-08-12'} - {source: 'https://security.salesforce.com/', http_status: 200, kind: security-program-hub, fetched: '2026-08-12'} - {source: 'https://compliance.salesforce.com/en/services/marketing-cloud-intelligence', http_status: 200, kind: pen-test-summary-listing, fetched: '2026-08-12', note: 'lists "Vulnerability/Penetration Report Summary - MC Intelligence (fka Datorama)"'} - {source: 'https://www.salesforce.com/.well-known/security.txt', http_status: 404, kind: security.txt, fetched: '2026-08-12'} probe_result: script: 0-working/probe-security-programs.py run: '2026-08-12' result: 'vdp=none' note: >- The mechanical probe found nothing because datorama.com 301s to a salesforce.com marketing page and every path on the datorama hosts returns a catch-all shell. This file is the searched upgrade over that null result.